This Privacy Policy describes how Leap Services, Inc. (“Leap” or “we,” “us,” or other forms thereof) may collect and process your personal information (“Personal Information”) in connection with your use of any Leap-powered brick-and-mortar stores, our websites and online hosted portals (including at https://www.leapinc.com/), our mobile applications, and any of our related services (collectively, the “Services”). This Privacy Policy describes what Personal Information we collect about you in relation to your use of the Services, how we collect it, how we use it, with whom we may share it, and what rights you have regarding it.
Please read this Privacy Policy carefully. By providing us with any of your Personal Information or otherwise accessing or using any of our Services (including by visiting or conducting a transaction at any of our stores), you agree that you have read and understand this Privacy Policy and that you accept and consent to the privacy practices (and any uses and disclosures of Personal Information about you) that are described in this Privacy Policy.
In addition, as a consumer, certain of your Personal Information may be collected by or on behalf of our brand customers (“Brands”) independently of the Services. Any such independently collected Personal Information is referred to herein as “Brand Customer Data”. Brand Customer Data may be subsequently provided to or shared with Leap directly by Brands in connection with their use of our Services. However, Brand Customer Data is NOT subject to this Privacy Policy and is instead governed by the applicable Brand’s privacy policy. Brands are solely responsible for their use of Brand Customer Data, and we encourage you to read and become familiar with each Brand’s privacy policy to understand how they may independently collect, use, and share with others (including with Leap) Brand Customer Data before submitting your Personal Information to them.
Personal Information We Collect
You may provide Personal Information to Leap when you visit our website, shop in our retail stores, sign up through the Services for marketing emails from Leap or the Brands, or otherwise access or use any of our other Services. We may combine that information with Personal Information that we obtain from our Brands (including Brand Customer Data), in accordance with our service agreements with each Brand.
Personal Information that we may collect through your use of our Services may include:
• Contact data, such as your first and last name, email address, billing and mailing addresses, and phone number;
• Transactional data, such as the information needed to complete your orders on or through the Services (including name, credit card information, and billing and shipping information), and your purchase history;
• Marketing data, such as your preferences for receiving communications about products services, events, promotions, and publications offered or made available through our Services, and details about how you engage with our communications;
• Communications that we exchange, including when you contact us with questions, feedback, or otherwise;
• Research data that you provide when you agree to participate in our surveys or research activities, such as your survey responses;
• Internet activity that includes browsing history, search history, and similar information on an individual’s interactions with the Services;
• Demographic information, including anonymized data about your age or gender;• Combined data that is a combination of any of the foregoing types of data or any data obtained from automatic data collection as described below; and
• Inference data that may be drawn from any of the information above, such as information about your purchase preferences, shopping interests, products interests, and store interests.
Automatic data collection. We may automatically collect information about you, your computer, or mobile device, and your interactions over time with our Services and other related sites and online services, including:
• Device data, such as your device operating system type and version number, manufacturer and model, browser type, screen resolution, IP address, unique identifiers, and location information (such as city, state or geographic area);
• Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access;
• Information collected by cookies and similar tracking technologies. Cookies are text files that websites store on a visitor’s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purposes of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, helping us understand user activity and patterns, and facilitating online advertising;
• In-store sensor data, such as information collected about visitors to our stores from video cameras, smartphone detectors, Wi-Fi networks, and other devices. For example, we collect information from Wi-Fi signals sent by your mobile device when you visit our stores, including unique identifiers, along with the time, signal strength, and location of the sensor that observed your device. We may use this information to measure visit durations; and
• Security camera footage from our stores. Visual tracking technologies. At stores, we may use visual tracking technologies, including cameras, to collect information related to you. This information will include only your assumed gender and approximate age. This information will NOT include any other information, and will not include your image, likeness, or any other biometric information about you.Information you provide to us. We may collect your Personal Information through the Services, including when you:
• Fill in forms on the Services, including when you inquire about our Services, sign up or register to use the Services, or request further services;
• Enter a contest or promotion sponsored by us;
• Send us a communication or other correspondence, including when you report a problem with our website, mobile app, or any of our other Services;
• Visit one of our stores;
• Browse our Services online;
• Respond to surveys that we might ask you to complete for research purposes;
• Make purchases or conduct any other transactions via the Services or in our stores; and
• Otherwise communicate with us or access or use any of our Services.
How Your Personal Information Is Used
We do not rent or sell your personal information.
We may use your Personal Information for the following purposes or as otherwise described at the time we collect it:
Services operations. We may use your Personal Information to:
• Provide, operate, and improve the Services and our business;
• Establish and maintain your user profile on the Services;
• Fulfill the orders you place through the Services;
• Conduct research and analytics to support our business, including through the creation and use of de-identified and/or aggregated data that is not reasonably identifiable to you; and
• Communicate with you about the Services, including by sending announcements, updates, and support and administrative messages.
Marketing and advertising. We may use your Personal Information for marketing and advertising purposes as described below:
• We may send you marketing communications as permitted by law, including by email and mail;
• We may contract with service providers to deliver advertising campaigns online. These campaigns may use cookies and similar technologies to collect information about you (including the device data, online activity data, and/or location data described above) over time and across our Services and other sites and services or your interaction with our emails, and use that information to serve ads that we think will interest you; and
• With your consent, we may publish testimonials and comments from you and identify you by your name and/or city.Compliance and protection. We may use your Personal Information to:
• Comply with our contractual obligations and applicable laws, regulatory requirements, and legal processes, such as to respond to subpoenas or requests from government authorities;
• Protect your and/or other users’ rights, privacy, safety, security, or property (including by making and defending legal claims and conducting security monitoring in our stores);
• Audit our internal processes for compliance with legal and contractual requirements and internal policies; and
• Enforce the terms and conditions that govern the Services.Application evaluation. For Brands, we may use the Personal Information relating to a Brand’s personnel in connection with a Brand’s application for a potential business engagement with Leap as a brand customer. This includes use in connection with:
• Processing your application;
• Assessing your capabilities and qualifications to be a brand customer; and
• Conducting background and reference checks if we enter into a relationship with you.
How Your Personal Information Is Shared
Brands. We may share your Personal Information with our Brands, including with Brands with whom you have transacted or interacted with at any time in the past, for the purposes described in this Privacy Policy.
Service providers. We engage service providers to provide us with a variety of services, including marketing services, social media advertising, payment processing, order fulfillment and shipping, data management, in-store analytics, and other services in connection with our business. We may disclose your Personal Information to these service providers for a business purpose in order to enable us to provide our Services to you. We may also disclose aggregated, de-identified information, and analyses and reports derived from such information, to our service providers. We require all of our service providers to use your Personal Information in a manner consistent with this Privacy Policy.
Legal requirements and business transfers. We may disclose your information:
• If we are required to do so by law, legal process, statute, rule, regulation, or professional standard, or to respond to a subpoena, search warrant, or other government official request;
• When we believe disclosure is necessary or appropriate to prevent physical harm or financial loss;
• In connection with an investigation of a complaint, security threat, or suspected or actual illegal activity;
• In connection with an internal audit; or
• In the event that Leap is subject to mergers, acquisitions, joint ventures, sales of assets, reorganizations, divestitures, dissolutions, bankruptcies, liquidations, or other types of business transactions. In these types of transactions, your information (including Personal Information) may be shared, sold, or transferred, and it may be used subsequently by a third party.
Other Sites and Services
The Services may contain links to websites, mobile applications, and other online services operated by third parties. These links are not an endorsement of, or representation that we are affiliated with, any third party. In addition, our content may be included on web pages or in mobile applications or other online services that are not associated with us. We do not control websites, mobile applications, or online services operated by third parties, and we are not responsible for their actions. You should consult the privacy policies at those third-party websites, mobile applications, and online services to determine what information they collect and how your information may be used.
Security
We employ a number of technical, organizational, and physical safeguards designed to protect the Personal Information we collect. However, security risk is inherent in all internet and information technologies and we cannot and do not guarantee the security of your Personal Information.
Data Retention
We will keep your Personal Information (including your Personal Information in each category described in the “Your State Privacy Rights” section below, if applicable) only for the period necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is permitted or required by law.
Do Not Track Notice
While we take reasonable steps to protect the privacy of our website visitors, we cannot promise that the current limitations of our online applications programming will address every browser setting or honor every personal browser preference. In particular, we have not implemented the necessary program changes to honor “Do Not Track” or “DNT” browser signals. As our online applications programming is refined, we will take reasonable steps to honor such requests in the future. Please return to this Privacy Policy for further updates on this topic.
International Data Transfer
We are headquartered in the United States and may use service providers that operate in other countries. Your Personal Information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.
If you are not a resident of the United States, you acknowledge and agree that we may collect and use your Personal Information outside your home jurisdiction, and that we may store your Personal Information in the United States or elsewhere. Please note that the level of legal protection provided in the United States from which you may access or use the Services may not be as stringent as that under the privacy laws of other countries, possibly including your home jurisdiction. Users from jurisdictions outside the United States visit us and use the Services at their own choice and risk.
Children
Our website and online services are not intended for use by children under 13 years of age, and we do not knowingly collect Personal Information from children under the age of 13 via our website or online services. If we learn that we have collected Personal Information from a person under the age of 13 via our website or online services and without the consent of the person’s parent or guardian as required by law, we will delete it. If you believe we might have any Personal Information from or about a child under the age of 13, please contact us at support@leapinc.co.
Your State Privacy Rights
Pursuant to certain state laws, including, if applicable, the California Consumer Privacy Act (“CCPA”), Leap makes the following disclosures regarding the Personal Information we collect:
Other than for a business purpose as described in this Privacy Policy, we have not sold or shared consumers’ Personal Information in the 12 months preceding the effective date of this Privacy Policy.
Under certain state laws, including, but not limited to, the CCPA, you may have the right to request:
• The categories of Personal Information we have collected about you;
• The categories of sources from which your Personal Information is collected;
• The business or commercial purpose of collecting or selling your Personal Information;
• The categories of third parties with whom we share your Personal Information;
• The specific pieces of Personal Information we have collected about you;
• When and if applicable, the categories of Personal Information that we have sold about you and the categories of third parties to whom the Personal Information was sold, if applicable;
• Access to your Personal Information;
• Deletion of your Personal Information;
• Correction of inaccurate Personal Information we maintain about you;
• An opt out of having your Personal Information sold to third parties or shared with third parties for purposes of cross-context behavioral advertising (if applicable); and/or
• Limitation on use of any sensitive Personal Information we maintain about you to that which is necessary to provide a good or service requested by you (if applicable).
To submit a request, or designate an authorized agent to make a permitted request under an applicable state law on your behalf, please contact us at support@leapinc.co or (833) 946-2075. To verify your identity when you submit a request, we will match the identifying information you provide us to the Personal Information we have about you. If you have an account with us, we will also verify your identity through our existing authentication practices for your account. Requests will typically be honored within 45 days or less, but may take up to 90 days based on the results of verification. Note that certain state laws may limit the number of requests you may make within a 12-month period.
Notwithstanding any of the above, we will not be required to comply with your request to delete your Personal Information if it is necessary for us to maintain your Personal Information in order to:
• Complete the transaction for which the Personal Information was collected, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us;
• Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;
• Debug to identify and repair errors that impair existing intended functionality;
• Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
• Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code;
• Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the achievement of such research, if you have provided informed consent;
• To enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us;
• Comply with a legal obligation; or
• Otherwise use your Personal Information internally and in a lawful manner that is compatible with the context in which you provided the information.
We will not discriminate against you in the event you exercise any of the aforementioned rights under state laws, including, but not limited to, by:
• Denying goods or services to you;
• Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
• Providing a different level or quality of goods or services to you; or
• Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
This Privacy Policy is available to consumers with disabilities. To access this Privacy Policy in an alternative format, please contact us at support@leapinc.co.
EEA Data Subject Rights and Choices
We are headquartered in the United States and may use service providers that operate in other countries. Your Personal Information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.
By using the Services and providing Personal Information to us via the Services, you acknowledge and agree that your Personal Information may be transferred to the United States. If you do not wish to have your Personal Information transferred to the United States, do NOT use (or continue to use) the Services.
Under certain circumstances, individuals (“Data Subjects”) in the European Economic Area (“EEA”) may have the following rights under the EU General Data Protection Regulation (“GDPR”):
• Right to access the Personal Information we maintain about you;
• Right to be provided with information about how we process your Personal Information;
• Right to correct your Personal Information;
• Right to have your Personal Information erased;
• Right to object to or restrict how we process your Personal Information; and
• Right to request your Personal Information to be transferred to a third party.
To exercise the above rights, please contact us at the information provided below. We will consider and process your request within a reasonable period of time. Please be aware that under certain circumstances, the GDPR may limit your exercise of these rights.
How to Withdraw Consent. At any time, Data Subjects from the EEA may withdraw consent you have provided to us for using, disclosing, or otherwise processing your Personal Information. You may withdraw your consent by communicating your request at the information provided below.
Please note that your withdrawal of consent to process certain Personal Information about you (1) may limit our ability to deliver services to you and (2) does not affect the lawfulness of our processing activities based on your consent before its withdrawal. Note that even after withdrawing consent, we may use, disclose, or otherwise process your Personal Information if required by law to do so.
How to File a Complaint. Additionally, Data Subjects from the EEA may file a complaint with EU data protection authorities (“DPA”). A list of DPAs from the European Commission may be found here: http://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=50061.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make changes to this Privacy Policy, we will update the date of this Privacy Policy and post it on our website. If the changes are significant, we may provide a more prominent notice, and at our discretion may email you directly with notification of the changes, if we have an email address on file for you. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting) or other notice. In all cases, your continued use of the Services after the posting of any modified Privacy Policy or other notice indicates your acceptance of the modified Privacy Policy.
How to Contact Us
If you have any questions or concerns about this Privacy Policy, or to otherwise contact us in regards to this Privacy Policy, you can reach us by email at support@leapinc.co or by mail at Leap Services, Inc., 207 E. Ohio St. #115, Chicago, IL 60611.